Difference Between "FSSO Agent on Windows AD" and "LDAP Servers" Configuration in FortiGate
Hello community,
I am currently configuring FSSO in FortiGate to create identity-based firewall policies using Active Directory usernames/groups, and I have a question regarding two different configuration sections that seem related to AD integration.
I noticed there are two separate options in the GUI:
- Security Fabric > External Connectors > FSSO Agent on Windows AD

- User & Authentication > LDAP Servers

At the moment, I configured only the FSSO option and it is already learning users/groups correctly from Active Directory.
My question is:
- What is the functional difference between these two configurations?
- What is each option specifically used for?
- Is it necessary to configure both for identity-based policies?
- In which scenarios would LDAP configuration still be required if FSSO is already working?
From my understanding so far:
- FSSO is mainly used for transparent user identification (User ↔ IP mapping) based on Windows logon events.
- LDAP seems more focused on direct authentication and group querying from AD.
However, I would like to better understand the architecture and best practices, especially in environments where:
- policies are based on AD groups,
- user visibility in logs is required,
- and centralized identity-based access control is implemented.
I would appreciate clarification on how both features complement each other and when both should be configured together.
Thanks in advance.
